CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2024-43532

    Last Modified: 9 Jun 2026

    Remote Registry Service Elevation of Privilege Vulnerability

    Published: 8 Oct 2024
    7.3
    High

    CVE-2024-43529

    Last Modified: 9 Jun 2026

    Windows Print Spooler Elevation of Privilege Vulnerability

    Published: 8 Oct 2024
    7.8
    High

    CVE-2024-43527

    Last Modified: 9 Jun 2026

    Windows Kernel Elevation of Privilege Vulnerability

    Published: 8 Oct 2024
    6.8
    Medium

    CVE-2024-43526

    Last Modified: 9 Jun 2026

    Windows Mobile Broadband Driver Remote Code Execution Vulnerability

    Published: 8 Oct 2024
    6.8
    Medium

    CVE-2024-43525

    Last Modified: 9 Jun 2026

    Windows Mobile Broadband Driver Remote Code Execution Vulnerability

    Published: 8 Oct 2024
    8.8
    High

    CVE-2024-43519

    Last Modified: 9 Jun 2026

    Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability

    Published: 8 Oct 2024
    8.8
    High

    CVE-2024-43518

    Last Modified: 9 Jun 2026

    Windows Telephony Server Remote Code Execution Vulnerability

    Published: 8 Oct 2024
    7.5
    High

    CVE-2024-43515

    Last Modified: 9 Jun 2026

    Internet Small Computer Systems Interface (iSCSI) Denial of Service Vulnerability

    Published: 8 Oct 2024
    6.4
    Medium

    CVE-2024-43513

    Last Modified: 9 Jun 2026

    BitLocker Security Feature Bypass Vulnerability

    Published: 8 Oct 2024
    5.5
    Medium

    CVE-2024-43508

    Last Modified: 9 Jun 2026

    Windows Graphics Component Information Disclosure Vulnerability

    Published: 8 Oct 2024
    7.5
    High

    CVE-2024-43506

    Last Modified: 9 Jun 2026

    BranchCache Denial of Service Vulnerability

    Published: 8 Oct 2024
    7.8
    High

    CVE-2024-43505

    Last Modified: 9 Jun 2026

    Microsoft Office Visio Remote Code Execution Vulnerability

    Published: 8 Oct 2024
    7.8
    High

    CVE-2024-43504

    Last Modified: 9 Jun 2026

    Microsoft Excel Remote Code Execution Vulnerability

    Published: 8 Oct 2024
    7.8
    High

    CVE-2024-43503

    Last Modified: 9 Jun 2026

    Microsoft SharePoint Elevation of Privilege Vulnerability

    Published: 8 Oct 2024
    7.1
    High

    CVE-2024-43502

    Last Modified: 9 Jun 2026

    Windows Kernel Elevation of Privilege Vulnerability

    Published: 8 Oct 2024
    6.5
    Medium

    CVE-2024-43481

    Last Modified: 8 Jul 2025

    Power BI Report Server Spoofing Vulnerability

    Published: 8 Oct 2024
    6.6
    Medium

    CVE-2024-43480

    Last Modified: 9 Jun 2026

    Azure Service Fabric for Linux Remote Code Execution Vulnerability

    Published: 8 Oct 2024
    7.8
    High

    CVE-2024-38261

    Last Modified: 9 Jun 2026

    Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

    Published: 8 Oct 2024
    8.8
    High

    CVE-2024-38179

    Last Modified: 9 Jun 2026

    Azure Stack Hyperconverged Infrastructure (HCI) Elevation of Privilege Vulnerability

    Published: 8 Oct 2024
    7.8
    High

    CVE-2024-43516

    Last Modified: 9 Jun 2026

    Windows Secure Kernel Mode Elevation of Privilege Vulnerability

    Published: 8 Oct 2024
    7.1
    High

    CVE-2024-38097

    Last Modified: 8 Jul 2025

    Azure Monitor Agent Elevation of Privilege Vulnerability

    Published: 8 Oct 2024
    9.8
    Critical

    CVE-2024-3057

    Last Modified: 15 Apr 2026

    A flaw exists whereby a user can make a specific call to a FlashArray endpoint allowing privilege escalation.

    Published: 8 Oct 2024
    8.7
    High

    CVE-2024-8626

    Last Modified: 10 Oct 2024

    Due to a memory leak, a denial-of-service vulnerability exists in the Rockwell Automation affected products. A malicious actor could exploit this vulnerability by performing multiple actions on certain web pages of the product causing the affected products to become fully unavailable and require a power cycle to recover.

    Published: 8 Oct 2024
    7.5
    High

    CVE-2024-47011

    Last Modified: 16 Oct 2024

    Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information

    Published: 8 Oct 2024
    7.3
    High

    CVE-2024-47010

    Last Modified: 16 Oct 2024

    Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.

    Published: 8 Oct 2024
    7.3
    High

    CVE-2024-47009

    Last Modified: 16 Oct 2024

    Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.

    Published: 8 Oct 2024
    7.5
    High

    CVE-2024-47008

    Last Modified: 16 Oct 2024

    Server-side request forgery in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information.

    Published: 8 Oct 2024
    7.5
    High

    CVE-2024-47007

    Last Modified: 16 Oct 2024

    A NULL pointer dereference in WLAvalancheService.exe of Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to cause a denial of service.

    Published: 8 Oct 2024
    7.8
    High

    CVE-2024-9167

    Last Modified: 13 Aug 2025

    Under specific circumstances, insecure permissions in Ivanti Velocity License Server before version 5.2 allows a local authenticated attacker to achieve local privilege escalation.

    Published: 8 Oct 2024
    7.2
    High

    CVE-2024-9381

    Last Modified: 16 Oct 2024

    Path traversal in Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to bypass restrictions.

    Published: 8 Oct 2024
    7.2
    High

    CVE-2024-9380

    Last Modified: 24 Oct 2025

    An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to obtain remote code execution.

    Published: 8 Oct 2024
    6.5
    Medium

    CVE-2024-9379

    Last Modified: 24 Oct 2025

    SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.

    Published: 8 Oct 2024
    8.2
    High

    CVE-2024-9124

    Last Modified: 22 Sept 2025

    A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 600T. If the device is overloaded with requests, it will become unavailable. The device may require a power cycle to recover it if it does not re-establish a connection after it stops receiving requests.

    Published: 8 Oct 2024
    8.8
    High

    CVE-2024-7612

    Last Modified: 18 Dec 2024

    Insecure permissions in Ivanti EPMM before 12.1.0.4 allow a local authenticated attacker to modify sensitive application components.

    Published: 8 Oct 2024
    3.5
    Low

    CVE-2024-47951

    Last Modified: 11 Oct 2024

    In JetBrains TeamCity before 2024.07.3 stored XSS was possible via server global settings

    Published: 8 Oct 2024
    3.5
    Low

    CVE-2024-47950

    Last Modified: 11 Oct 2024

    In JetBrains TeamCity before 2024.07.3 stored XSS was possible in Backup configuration settings

    Published: 8 Oct 2024
    4.9
    Medium

    CVE-2024-47949

    Last Modified: 11 Oct 2024

    In JetBrains TeamCity before 2024.07.3 path traversal allowed backup file write to arbitrary location

    Published: 8 Oct 2024
    4.9
    Medium

    CVE-2024-47948

    Last Modified: 11 Oct 2024

    In JetBrains TeamCity before 2024.07.3 path traversal leading to information disclosure was possible via server backups

    Published: 8 Oct 2024
    4.3
    Medium

    CVE-2024-47161

    Last Modified: 11 Oct 2024

    In JetBrains TeamCity before 2024.07.3 password could be exposed via Sonar runner REST API

    Published: 8 Oct 2024
    8.7
    High

    CVE-2024-8215

    Last Modified: 16 Oct 2024

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Payara Platform Payara Server (Admin Console modules) allows Remote Code Inclusion.This issue affects Payara Server: from 5.20.0 before 5.68.0, from 6.0.0 before 6.19.0, from 6.2022.1 before 6.2024.10, from 4.1.2.191.1 before 4.1.2.191.51.

    Published: 8 Oct 2024
    7.2
    High

    CVE-2024-45330

    Last Modified: 19 Oct 2024

    A use of externally-controlled format string in Fortinet FortiAnalyzer versions 7.4.0 through 7.4.3, 7.2.2 through 7.2.5 allows attacker to escalate its privileges via specially crafted requests.

    Published: 8 Oct 2024
    3.3
    Low

    CVE-2024-33506

    Last Modified: 21 Jan 2025

    An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiManager 7.4.2 and below, 7.2.5 and below, 7.0.12 and below allows a remote authenticated attacker assigned to an Administrative Domain (ADOM) to access device summary of unauthorized ADOMs via crafted HTTP requests.

    Published: 8 Oct 2024
    —
    Unknown

    CVE-2024-9625

    Last Modified: 11 Feb 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 8 Oct 2024
    4.3
    Medium

    CVE-2024-8431

    Last Modified: 15 Apr 2026

    The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajaxGetGalleryJson() function in all versions up to, and including, 3.2.21. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve private post titles.

    Published: 8 Oct 2024
    6.4
    Medium

    CVE-2024-8482

    Last Modified: 8 Apr 2026

    The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 1.3.982 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 8 Oct 2024
    6.1
    Medium

    CVE-2024-9207

    Last Modified: 15 Apr 2026

    The BuddyPress Docs plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.2.3. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 8 Oct 2024
    4.4
    Medium

    CVE-2024-8488

    Last Modified: 8 Apr 2026

    The Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Survey fields in all versions up to, and including, 4.9.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

    Published: 8 Oct 2024
    9.8
    Critical

    CVE-2024-8884

    Last Modified: 15 Apr 2026

    CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause exposure of credentials when attacker has access to application on network over http

    Published: 8 Oct 2024
    7.3
    High

    CVE-2024-9005

    Last Modified: 15 Apr 2026

    CWE-502: Deserialization of Untrusted Data vulnerability exists that could allow code to be remotely executed on the server when unsafely deserialized data is posted to the web server.

    Published: 8 Oct 2024
    3.3
    Low

    CVE-2024-8518

    Last Modified: 15 Apr 2026

    CWE-20: Improper Input Validation vulnerability exists that could cause a crash of the Zelio Soft 2 application when a specially crafted project file is loaded by an application user.

    Published: 8 Oct 2024